Privacy Policy
AI Change Approval · Last updated 16 September 2026
Who this covers
AI Change Approval is a Shopify app operated by EC Web. This policy explains what the app stores when a merchant installs it, why, and for how long. It applies to the app only — not to your Shopify store itself, which is governed by Shopify’s own privacy policy.
What the app does
The app sits between an AI assistant and your Shopify store. The assistant cannot write to your store; it can only propose a change. The app reads the current state of whatever the proposal touches, works out a before-and-after diff, and holds it until a person approves it in your Shopify admin. Storing those proposals, and the record of what was approved and applied, is the purpose of the app and the reason most of the data below exists.
What is stored
| Data | Why |
|---|---|
| Your shop — myshopify.com domain, store name, currency, timezone, contact email, and which plan you are on | To identify your store, show money in the right currency, and send notifications you have asked for |
| Shopify access credentials — the offline access token Shopify issues at install, and the staff details Shopify includes in a session (user id, name, email, locale) | To read and write the resources you approve, and to record who approved something |
| Proposed and applied changes — the resource, the proposed values, and a snapshot of the affected fields before and after the change. These snapshots contain your own store content: product titles and descriptions, SEO fields, page and blog content, menu items, discounts (including the names of any customer segments a discount is limited to), markets, stock levels, image details, translations and metafields | To show you an accurate diff before you approve, to detect if the store changed underneath a pending proposal, and to undo a change afterwards |
| The audit trail — who approved, rejected, applied or reverted each change, when, and any reason given | To give you a record of what reached your store and who allowed it |
| Connection tokens — the name of each AI client you connect, which staff member approved it, when it was last used, and a one-way hash of the token itself | To let you see and revoke connections. The token is never stored in a form we can read back |
| Your settings — which resource types the app may touch, auto-approval rules, notification preferences | To do what you have configured |
| IP addresses of callers to the two public sign-in endpoints | Rate limiting, so those endpoints cannot be hammered. Kept for about two hours and never linked to a store |
| A log of emails sent — your shop domain, which template, and which time window | To avoid sending you the same notification twice |
What is never collected
The app does not read or store customer records, orders, or payment details. It holds no permission for orders or payments at all.
It does hold Shopify’s permission to read customers, for one reason: Shopify grants the list of your customer segments only with that permission, and a discount can be limited to a segment. The app uses it to read segment names and ids, and nothing else — it never reads, stores or changes any individual customer’s name, email, address or order history, and it cannot aim a discount at a named person. You can see exactly which permissions it holds on its listing and in your admin.
There is no analytics, tracking or advertising code in the app. Nothing is sold, rented or shared for marketing, and your store content is never used to train any AI model.
AI clients you connect
This one deserves stating plainly. When you connect an AI client — Claude, for example — you are authorising it to look up resources in your store through this app, so that it can propose sensible changes. Store content it reads that way goes to that client’s operator, under their privacy policy, not ours. We do not choose which client you connect and we cannot control what it does with what it reads.
What the app does guarantee is the other direction: no connected client can write to your store. It has no tool to do so, and it cannot approve its own proposals. You can see every connected client in the app’s settings and revoke any of them at any time, which takes effect immediately.
Built-in Claude, on development stores only. On a Shopify development store — the kind used for building and for App Store review — the app can run Claude itself, so the app can be tried without connecting anything. When someone uses it, the request they type and the store content Claude looks up are sent to Anthropic, which runs Claude, through the same tools and limits as any connected client: it can propose, never approve. It is never offered on a live merchant store.
Who else processes this data
- Shopify — the source of the data and the platform the app runs inside.
- Fly.io — hosting and the database. The app and its data run in Fly’s London region.
- Anthropic — runs built-in Claude on development stores only (see above), and receives only what that Claude is asked and looks up.
- Resend — sends notification emails, and receives only the address and the content of the email itself. Used only when email notifications are enabled.
That is the complete list. There are no other third parties.
How long it is kept
- While the app is installed — your changes and audit trail are kept, because that record is the point of the app.
- When you uninstall — the access token and session are deleted at once. The change history is deliberately kept for 48 hours, so that reinstalling does not lose the record of what was written to your store.
- 48 hours after uninstalling — Shopify sends an erasure request and everything held for your shop is deleted: the store record, every change and its snapshots, settings, rules and connection tokens.
- Shorter-lived data — rate-limit records about two hours, incomplete sign-in attempts fifteen minutes, the email log thirty days.
Your rights
You can see everything the app holds about your store from inside the app: the queue, the full history with every diff, your settings and your connections. To have it all erased, uninstall the app — erasure follows automatically 48 hours later. If you want it erased sooner, or want a copy, write to us and we will do it.
Depending on where you are, you may also have statutory rights to access, correct, export, restrict or object to the processing of personal data. Use the contact below and we will respond.
Security
All traffic is over HTTPS. Tokens for connected AI clients are stored only as a one-way hash, so a copy of the database does not yield a working token, and each token is scoped to a single store — one leaked from one merchant cannot be pointed at another. Approving a connection can only be done from inside your own Shopify admin, by someone signed in to your store.
Changes to this policy
If what the app collects or who processes it changes, this page changes with it and the date at the top is updated. Material changes will also be announced in the app.
Contact
Questions or requests: hello@ec-web.co.uk